Vulnerabilities > Samsung > Android > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-12-05 CVE-2023-42561 Out-of-bounds Write vulnerability in Samsung Android 11.0/14.0
Heap out-of-bounds write vulnerability in bootloader prior to SMR Dec-2023 Release 1 allows a physical attacker to execute arbitrary code.
low complexity
samsung CWE-787
6.8
2023-12-05 CVE-2023-42564 Unspecified vulnerability in Samsung Android 12.0/13.0/14.0
Improper access control in knoxcustom service prior to SMR Dec-2023 Release 1 allows attacker to send broadcast with system privilege.
local
low complexity
samsung
5.5
2023-12-05 CVE-2023-42565 Unspecified vulnerability in Samsung Android 13.0/14.0
Improper input validation vulnerability in Smart Clip prior to SMR Dec-2023 Release 1 allows local attackers with shell privilege to execute arbitrary code.
local
low complexity
samsung
6.7
2023-12-05 CVE-2023-42568 Unspecified vulnerability in Samsung Android 12.0/13.0
Improper access control vulnerability in SmartManagerCN prior to SMR Dec-2023 Release 1 allows local attackers to access arbitrary files with system privilege.
local
low complexity
samsung
4.4
2023-11-07 CVE-2023-42527 Improper Input Validation vulnerability in Samsung Android 11.0/12.0
Improper input validation vulnerability in ProcessWriteFile of libsec-ril prior to SMR Nov-2023 Release 1 allows local attackers to expose sensitive information.
local
low complexity
samsung CWE-20
5.5
2023-11-07 CVE-2023-42533 Unspecified vulnerability in Samsung Android 12.0/13.0
Improper Input Validation with USB Gadget Interface prior to SMR Nov-2023 Release 1 allows a physical attacker to execute arbitrary code in Kernel.
low complexity
samsung
6.8
2023-11-07 CVE-2023-42534 Files or Directories Accessible to External Parties vulnerability in Samsung Android 12.0/13.0
Improper input validation vulnerability in ChooserActivity prior to SMR Nov-2023 Release 1 allows local attackers to read arbitrary files with system privilege.
local
low complexity
samsung CWE-552
5.5
2023-10-04 CVE-2023-30731 Unspecified vulnerability in Samsung Android 12.0/13.0
Logic error in package installation via debugger command prior to SMR Oct-2023 Release 1 allows physical attacker to install an application that has different build type.
low complexity
samsung
4.6
2023-09-06 CVE-2023-30706 Unspecified vulnerability in Samsung Android 11.0/12.0
Improper authorization in Samsung Keyboard prior to SMR Sep-2023 Release 1 allows attacker to read arbitrary file with system privilege.
network
low complexity
samsung
4.9
2023-09-06 CVE-2023-30709 Unspecified vulnerability in Samsung Android 11.0/12.0
Improper access control in Dual Messenger prior to SMR Sep-2023 Release 1 allows local attackers launch activity with system privilege.
local
low complexity
samsung
6.7